Apple Safari Fixes Cross-Origin Issue to Protect Users' Data
CVE-2024-44187

6.5MEDIUM

Key Information:

Vendor
Apple
Vendor
CVE Published:
17 September 2024

Summary

A vulnerability exists in Apple products due to improper handling of 'iframe' elements, which can lead to cross-origin data exfiltration. This security issue could enable malicious websites to unintentionally access sensitive user data from other domains. Apple has addressed this vulnerability in several updates, including Safari 18, visionOS 2, watchOS 11, macOS Sequoia 15, iOS 18, iPadOS 18, and tvOS 18, emphasizing the importance of keeping software up to date for personal data protection.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.